Webkul Qloapps vulnerabilities
14 known vulnerabilities affecting webkul/qloapps.
Total CVEs
14
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2023-36284P2HIGHCVSS 7.5PoCv1.6.02023-06-23
CVE-2023-36284 [HIGH] CWE-89 CVE-2023-36284: An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_fro
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
nvd
CVE-2025-67325P2CRITICALCVSS 9.8≤ 1.7.02026-01-08
CVE-2025-67325 [CRITICAL] CWE-434 CVE-2025-67325: Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows re
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
nvd
CVE-2023-30256P3MEDIUMCVSS 6.1PoCv1.5.22023-05-11
CVE-2023-30256 [MEDIUM] CWE-79 CVE-2023-30256: Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtai
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
nvd
CVE-2023-36287P3MEDIUMCVSS 6.1PoCv1.6.02023-06-23
CVE-2023-36287 [MEDIUM] CWE-79 CVE-2023-36287: An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
nvd
CVE-2023-36289P3MEDIUMCVSS 6.1PoCv1.6.02023-06-23
CVE-2023-36289 [MEDIUM] CWE-79 CVE-2023-36289: An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
nvd
CVE-2025-6173P3HIGHCVSS 7.2v1.6.12025-06-17
CVE-2025-6173 [HIGH] CWE-74 CVE-2025-6173: A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerabi
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor co
nvd
CVE-2024-40318P3HIGHCVSS 7.2v1.6.02024-07-25
CVE-2024-40318 [HIGH] CWE-434 CVE-2024-40318: An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitr
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
nvd
CVE-2025-10759P4MEDIUMCVSS 5.3≤ 1.7.0v1.0+7 more2025-09-21
CVE-2025-10759 [MEDIUM] CWE-285 CVE-2025-10759: A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We are already aware about this vulne
nvd
CVE-2023-36235P4MEDIUMCVSS 6.5fixed in 1.6.02024-01-17
CVE-2023-36235 [MEDIUM] CWE-639 CVE-2023-36235: An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
nvd
CVE-2025-1155P4MEDIUMCVSS 6.1v1.6.12025-02-10
CVE-2025-1155 [MEDIUM] CWE-79 CVE-2025-1155: A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affect
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term.
nvd
CVE-2021-41074P4MEDIUMCVSS 5.4v1.5.12026-01-12
CVE-2021-41074 [MEDIUM] CWE-352 CVE-2021-41074: A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's
A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
nvd
CVE-2023-36288P4MEDIUMCVSS 5.4v1.6.02023-06-23
CVE-2023-36288 [MEDIUM] CWE-79 CVE-2023-36288: An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
nvd
CVE-2025-1074P4MEDIUMCVSS 4.3v1.6.12025-02-06
CVE-2025-1074 [MEDIUM] CWE-352 CVE-2025-1074: A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was
nvd
CVE-2025-26058P4MEDIUMCVSS 4.2v1.6.12025-02-18
CVE-2025-26058 [MEDIUM] CWE-598 CVE-2025-26058: Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access th
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
nvd